An attacker bought 30 WordPress plugins and injected backdoors that use Ethereum smart contracts to resolve their C2 domains — a supply chain attack you can't take down. Plus: the real lesson from the 'AI vibe coding horror story,' why Backblaze silently stopped backing up customer data, and how Erik runs checksums on 64 projects to catch exactly this kind of drift. Pro tip: when to trust AI-generated code and when to verify every line.